Skip to content

Confidential Β· 29 Jun 2026

πŸ›‘οΈ Daily Cybersecurity Briefing β€” 2026-06-29 (Sunday)

Window: last 72h (June 26–29). Severity: πŸ”΄ CRITICAL Β· 🟑 HIGH Β· 🟒 MEDIUM. Last updated: 2026-06-29T19:04Z.

Threat level ELEVATEDVictims L30D 273Top actor QilinM&A L30D $70M

πŸ’Ό M&A ACTIVITY

No new M&A deals announced June 26–29.MediumThe June 2026 monthly roundup is expected June 30 when the month closes.
L30D summary (May 30–Jun 29):7 named deals, ~$4.48B+ total disclosed value. Largest: Accentureβ†’Dragos/runZero/NetRise ($4.1B OT security platform, Jun 18); Dream $260M Series C sovereign AI defense (Jun 18); Ciscoβ†’WideField NHI/agentic SOC (Jun 19); Databricksβ†’Panther AI-native SIEM (Jun 16); Cyeraβ†’Otterize cloud-native NHI (Jun 26). Theme: non-human identity (NHI), agentic AI security, and OT/ICS consolidation dominate the quarter.

⚠️ CRITICAL BREACHES & INCIDENTS

KDDI Corporation (Japan) β€” 14.22 million email subscriber accountsHighcompromised via a vulnerability in third-party email management software. Affected ISPs managed by KDDI: Chuokai, Johoku Communications, KCN Kyoto, Okayama Information Highway, Sanin Godo Bank Net, Tokai Broadband. KDDI began customer notifications June 24–28; scope limited to email account records. Actor unattributed. The Record Β· SecurityWeek
NSW Rural Fire Service (Australia) β€” Nova ransomware claimed 300 GBMediumof data exfiltrated. RFS confirmed the breach June 24 but said emergency operations were unaffected. Nova DLS claim June 26. Cyber Daily
FCCI Insurance Group and HologicHighboth listed on REDACT DLS June 28. REDACT is a Com-affiliated data extortion group assessed by Google GTIG as a BlackFile rebrand; uses vishing and evasive phishing, no traditional encryption. No victim statements. πŸŸ₯ Unverified β€” treat as claimed only. RedPacket Security
Ukrposhta (Ukraine national postal service) β€” cyberattack disrupted mobile app June 25.MediumPro-Russian hacktivist group IT Army of Russia claimed responsibility, alleging it had breached Ukrposhta's infrastructure several weeks earlier and exfiltrated a database of user information. Mobile application and some digital services were temporarily down; physical post office operations unaffected. Ukrposhta confirmed the attack but did not disclose data compromise scope. Previously uncaptured β€” missed in June 25 runs. The Record Β· Kyiv Post
Splunk CVE-2026-20253 β€” federal remediation deadline OVERDUE (was June 21).CriticalCVSS 9.8 unauthenticated RCE. CISA BOD 26-04 required federal agency patching 8 days ago. Agencies not compliant face BOD escalation. WatchTowr PoC
CVE-2026-12957 / CVE-2026-12958 β€” Amazon Q Developer MCP auto-execution β€” CVSS 8.5 β€” disclosed June 26.HighWiz Research found that the Amazon Q Developer IDE extension auto-loaded and executed MCP server configs from any opened repository without user consent; a single malicious `.amazonq/mcp.json` file silently exfiltrated active AWS session credentials when a developer cloned the repo. A companion flaw CVE-2026-12958 covers symlink traversal in MCP configs. No public exploitation recorded; fixed in Amazon Q extension v1.69.0+. Illustrates an emerging attack class: supply-chain credential theft via AI developer tooling, requiring only a public repository and a single config file. Wiz Blog Β· The Register Β· The Hacker News

πŸ”“ CRITICAL VULNERABILITIES

CVE-2026-46331 "pedit COW" β€” Linux kernel LPE β€” CVSS 7.8 β€” public exploit appeared June 17.HighA second Linux kernel local privilege escalation in the same window as DirtyClone (CVE-2026-43503): missing bounds check in `tcf_pedit_act()` (traffic-control packet-editing) allows an unprivileged local user to corrupt page-cache memory and poison setuid-root binaries, achieving a root shell without touching disk β€” file-integrity monitoring returns clean. Upstream kernel patched; Red Hat RHEL 8/9/10, Debian 11/12/13, and Ubuntu 18.04–26.04 patches available. Like DirtyClone, requires unprivileged user namespaces. Priority: patch container hosts, Kubernetes nodes, and multi-tenant Linux servers. The Hacker News Β· TuxCare Β· NVD
CVE-2026-20262 β€” Cisco SD-WAN Manager β€” CVSS 6.5 β€” federal deadline TODAY (June 29).HighAuthenticated path traversal enabling arbitrary file write on the OS (no workaround; upgrade to fixed release only); CISA KEV'd June 15 under BOD 26-04; federal agencies not patched face immediate escalation. CISA KEV Β· Help Net Security
CVE-2026-43503 "DirtyClone" β€” Linux kernel LPE β€” CVSS 8.8 β€” public exploit published June 27.CriticalCopy-on-Write exploitation via pedit/cls_u32 netfilter interaction; allows full-disk write access from an unprivileged local user; no kernel log trace. Highest risk: Kubernetes clusters, container runtimes, shared Linux servers. No upstream patch yet; mitigate by restricting cls_u32 access and disabling unprivileged eBPF. [Security researcher disclosure]
CVE-2026-12569 β€” PTC Windchill / FlexPLM β€” CVSS 10.0 β€” CISA KEV (Jun 25), deadline June 28 (YESTERDAY).HighUnauthenticated RCE; exploited in the wild; Germany BSI issued emergency alert. Critical manufacturing and engineering PLM systems at risk. CISA KEV Β· PTC Advisory
CVE-2026-20230 β€” Cisco Unified Communications Manager β€” CVSS 8.6 β€” CISA KEV (Jun 25), deadline June 28 (YESTERDAY).HighServer-Side Request Forgery enabling root file-write; active exploitation observed June 21–22. CISA KEV
CVE-2026-48558 β€” SimpleHelp RMM β€” CVSS 10.0 β€” actively exploited (Djinn Stealer + TaskWeaver).CriticalOIDC authentication bypass via forged JWT token: an unauthenticated attacker submits a crafted identity token to create a rogue Technician account granting full remote control of managed endpoints β€” script execution, data theft, software installation β€” with MFA bypass on first-registration. Approximately 14,000 internet-exposed SimpleHelp servers identified at disclosure (June 12). Active exploitation confirmed by Blackpoint MDR: threat actors deployed TaskWeaver loader then Djinn Stealer (new cross-platform infostealer; Windows/macOS/Linux) post-exploitation. MSPs, IT support providers, and managed service desks running SimpleHelp are the target population; a single compromised server exposes every managed endpoint in the operator's fleet. Patch immediately to SimpleHelp 5.5.16 / 6.0RC2 (released June 9). BleepingComputer Β· Horizon3.ai Β· Help Net Security

🚨 INTELLIGENCE AGENCY ALERTS & POLICY

CISA/FBI joint advisory (June 27): Russian intelligence targeting Signal Backup Recovery Keys.CriticalGRU and SVR operatives targeting individuals with access to Ukrainian military intelligence, European defense officials, and US government personnel. Attack vector: compromising Signal's Backup Recovery Key allows full message-history restore to an attacker-controlled device. Advisory recommends auditing linked devices, revoking all linked device sessions, and disabling Backup feature where operational security demands it. CISA
Five Eyes AI advisory (June 23): "Frontier AI capable of autonomous cyberattacks is months, not years away."CriticalUS, UK, Canada, Australia, and New Zealand issued rare joint statement warning boards of imminent agentic offensive AI β€” automated phishing, lateral movement, and full exploit chains with minimal human involvement. Advisory urges legacy infrastructure upgrades and board-level security investment. CNN Β· Industrial Cyber
APT28 (GRU Unit 26165) β€” DOJ/FBI Operation Masquerade: 18,000+ compromised SOHO routers neutralized.HighCourt-authorized disruption of global TP-Link botnet used for DNS hijacking of Microsoft OWA and government portals to harvest passwords and auth tokens. At peak (Dec 2025): 18,000+ unique IPs across 120+ countries. FBI commands reset DNS settings and collected forensic evidence without disrupting router function. DOJ Β· CyberScoop
Canada CSIS first-ever botnet neutralization warrant (public release June 22).MediumFederal Court authorized CSIS to actively modify and destroy botnet data on infected civilian devices (SOHO routers, Ring doorbells, cameras). Original warrant May 2024, public release June 2026. Sets precedent for intelligence-led active cyber defence. The Hacker News
FCC approved new undersea cable cybersecurity rules (June 2026).HighMandatory licensing for Submarine Line Terminal Equipment owners; restrictions on foreign-adversary-controlled entities; bans on covered equipment in submarine cable systems; new physical and cyber risk management plan requirements. CyberScoop Β· The Record

🌐 THREAT ACTOR & CAMPAIGN ACTIVITY

Ransomware DLS activity β€” June 26–29
Qilin (#1, YTD 546+):CriticalPosted NASCO (healthcare tech/US β€” processes Blue Cross Blue Shield administrative data for multiple BCBS plans) and Axionlog (logistics/supply chain) on June 29 β€” today's postings. Also posted 1-800-Dentist (consumer dental referral/US) and TransCore (transcore.com β€” electronic toll collection and intelligent transportation systems/US; serves 8 of 10 largest US tolling agencies; ST Engineering subsidiary) on June 28. All four πŸŸ₯ unverified. NASCO is the most significant healthcare infrastructure target; TransCore's toll infrastructure data would be strategically sensitive. ransomware.live Β· RedPacket Security
DragonForce (#4):HighClaimed Aptora (field service management SaaS/US, Lenexa KS) June 27; alleges databases of 100+ Aptora client companies were exfiltrated β€” potential software supply-chain downstream exposure. πŸŸ₯ Unverified. ransomware.live
Nova:HighNSW Rural Fire Service (300 GB, breach confirmed by RFS, emergency ops unaffected) and VSL Marine Technology (India) both posted June 26.
REDACT (new actor):HighFCCI Insurance Group and Hologic (~$4B medical device company) posted June 28. Com-affiliated; Google GTIG assesses as BlackFile rebrand. πŸŸ₯ Unverified.
Interlock:MediumClearview Eye Centre (ophthalmology/Calgary, Canada) posted June 26. πŸŸ₯ Unverified. DeXpose
INC Ransom:MediumTwo US personal injury law firms (Horton Personal Injury Lawyers, Law Office of John Dufour) posted June 26; GDN AR (Dorinka S.R.L., grocery/Argentina) posted June 29. All πŸŸ₯ unverified. ransomware.live
SafePay:Mediumhellmold-plank.de (German manufacturer, roots to 1904) posted June 27. πŸŸ₯ Unverified.
LeakNet:MediumMagMutual Insurance (US healthcare professional insurer) posted June 26. πŸŸ₯ Unverified.
The Gentlemen (#2, YTD 335+):CriticalClaimed Thyssenkrupp Marine Systems (TKMS) GmbH / Atlas Elektronik (defense electronics/Germany) on June 28; estimated attack June 25. Atlas Elektronik makes submarine sonar systems, acoustic sensors, and heavyweight torpedo guidance for the German Navy and allied export customers. If the claim is genuine, any exfiltrated data could include naval systems specifications or classified program material. πŸŸ₯ Unverified β€” no TKMS or Atlas Elektronik statement. ransomware.live
Payload:MediumMosaic Partners (Swiss IT services/software development) posted June 26. πŸŸ₯ Unverified. DeXpose Β· RedPacket Security
SETTRA (new actor, June 2026 debut):MediumClaimed Turbo Data Systems (turbodata.com, US data broker/technology sector) on June 28; estimated attack June 17. SETTRA operates via a Tor onion extortion link and has 11 known victims across its brief history. πŸŸ₯ Unverified. ransomware.live Β· RedPacket Security
Play:MediumClaimed Kuhnline (kuhnline.com), a German construction company, on June 27. Data scope unconfirmed. πŸŸ₯ Unverified. ransomware.live
Payload:MediumThree victims posted June 26 β€” Mosaic Partners (Swiss IT services/software dev), Software Arge (Turkish enterprise data analytics), and Payload Corporation (payloadcorp.com β€” US fintech/B2B payments platform serving real estate, legal, and insurance sectors; coincidence of name). All three πŸŸ₯ unverified β€” no victim statements. DeXpose Β· RedPacket Security
Stormous (June 28 DLS batch β€” 5 new victims):HighHiguchi Inc. (industrial manufacturing/Japan) and its US subsidiary HIGUCHI USA, INC. (Dallas) β€” full financial statements exfiltrated; EOGB Energy Products Ltd (UK oil/gas/dual-fuel burner manufacturer) β€” Microsoft Dynamics GP corporate accounting and legal records accessed; ESHA Research/ESHA Cloud Services (food/nutrition database software, Salem OR) β€” core product development databases breached; Monoprix.tn (Tunisian retail chain). All five claimed June 28, 2026. All πŸŸ₯ unverified β€” no victim statements. HookPhish Β· ransomware.live Β· SOCRadar
WorldLeaks (ex-Hunters International) β€” Nike, Inc. breach (June 23, full data dump live):Critical1.4TB claimed; 188,347 files alleged to include R&D technical packs, BoMs, product prototypes, and manufacturing schematics. Full data dump published. Nike confirmed it is investigating and has engaged external cybersecurity experts. 🟨 Breach under investigation β€” scope and data authenticity not independently verified. Note: this claim predates the June 26–29 window but the full dump went live during it. Infosecurity Magazine Β· Dark Reading
APT / Nation-State
Russian intelligence (GRU/SVR) targeting Signal usersCriticalvia compromised Backup Recovery Keys β€” see advisory above.
APT28 TP-Link botnet (Operation Masquerade) disruptedHighby DOJ/FBI court-authorized operation β€” see advisory above.
StrikeShark campaign (Kaspersky GReAT, June 24): new unattributed APT delivers Cobalt Strike via novel SharkLoader dropper.HighTargets include diplomatic entities in Indonesia, government agencies in Taiwan, and organizations in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia. Initial access: exploitation of internet-facing Microsoft Exchange, SharePoint, and Openfire servers β€” or via fake Google Update / Cisco AnyConnect installers. Post-compromise chain: DLL side-loading of legitimate Windows binaries to load encrypted modules, API-hook installation to evade EDR, then Cobalt Strike Beacon injection. No attribution to a known APT group; Kaspersky continues tracking activity. High-confidence APT profile: target selection (governments, diplomats, software developers across multiple continents), custom tooling, and EDR-evasion sophistication rule out financially motivated actors. Kaspersky/Securelist Β· The Hacker News Β· Help Net Security

🌍 GEOPOLITICS

Russia is running simultaneous operations against both the messaging layer and enterprise email infrastructure β€” a two-pronged credential collection posture.CriticalThe CISA/FBI Signal advisory and Operation Masquerade reveal that GRU/SVR are compromising Signal Backup Recovery Keys (personal comms) while simultaneously running DNS-hijacking against OWA and government portals (enterprise email). Any official or defense contractor who communicates across both channels is doubly exposed. Prioritize auditing Signal linked devices and checking FortiGate/OWA exposure this week.
The Five Eyes "months, not years" AI advisory forces a near-term planning horizon, not a forecast to track.CriticalSecurity architectures built around human-paced attackers β€” manual approvals, 24-hour detection windows, quarterly patching cycles β€” are not adequate against autonomous agentic attacks. Boards that treat this as a 2027 problem are already behind. The immediate defensive implication: prioritize detection and response speed, not just prevention.
NASCO's appearance on Qilin's DLS is the most systemically significant healthcare claim of the June 26–29 window.HighNASCO processes administrative data for multiple Blue Cross Blue Shield plans nationwide. If confirmed, scope could include enrollment, claims, and member data across dozens of BCBS affiliate plans covering tens of millions of Americans. Monitor the DLS entry for proof-of-data publication before drawing conclusions.
The Aptora DLS claim, if true, represents a software supply-chain attack on US field service infrastructure.HighAptora's SaaS platform is used by contractors across utilities, facilities management, and healthcare services. If 100+ client databases were exfiltrated, the exposure surface is far broader than Aptora itself. Aptora's downstream client list should be treated as the actual risk population.
Canada's CSIS botnet neutralization warrant sets an active-defence precedent with Five Eyes implications.MediumCourt-authorized modification and destruction of botnet data on infected civilian devices is a significant legal step. The UK NCSC, US NSA, and Australian ASD will likely cite the Canadian model in their own policy processes β€” watch for similar legislative moves in 2026 H2.
The Gentlemen's claimed breach of TKMS/Atlas Elektronik is the most strategically sensitive ransomware claim of this window.CriticalAtlas Elektronik develops submarine sonar, acoustic measurement, and torpedo guidance systems; its customer list includes the German Navy and allied export partners. Even an unverified claim warrants immediate verification: if the intrusion is real and involved engineering networks, classified naval program data may be at risk. Germany's BSI and relevant defence commands should be on notice pending TKMS disclosure.
Russian attribution of the August 2025 JLR attack closes the loop on the UK's most costly cyberattack β€” and leaves the state-criminal boundary deliberately undefined.HighNYT investigation (June 26) confirmed investigators from the FBI, UK NCA, NCSC, Mandiant, and Palo Alto Networks linked the attack to a Russian group tracked by Microsoft, which alerted JLR directly. Production halted five to six weeks across all JLR plants; estimated economic cost Β£1.9B ($2.5B); UK government backstopped with nearly Β£500M in loan guarantees. Whether the group acted for profit, on Kremlin orders, or with tacit state approval remains formally unresolved β€” the same ambiguity that characterises Operation Masquerade and the SVR/GRU signal operations disclosed this same week. The pattern is consistent with Russia's strategy of using proximate criminal infrastructure as a national-security tool while retaining plausible deniability. TechCrunch Β· SC Media Β· Infosecurity Magazine
Threat actors
1 Β· Qilin546 YTD
2 Β· The Gentlemen335 YTD
3 Β· Akira228 YTD
4 Β· DragonForce248 YTD
M&A activity
Socure β†’ Fravityβ€”
Brinqa β†’ PlexTracβ€”
Munich Re (via HSB) β†’ $575Mβ€”
Fortinet β†’ Virtue AIβ€”